
ISSO / RMF Cybersecurity Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Virginia.
• Oversee the categorization of systems, selection of security controls, implementation, assessment, and ongoing monitoring throughout the RMF lifecycle.
• Create, revise, and sustain Security Authorization Packages, which include SSPs, SARs, POA&Ms, and plans for continuous monitoring.
• Utilize government record systems such as eMASS to record and manage compliance packages.
• Organize and execute vulnerability scans with tools like ACAS, Nessus, and SCAP Compliance Checker.
• Evaluate scan findings, coordinate vulnerability remediation efforts with technical teams, and document exceptions or POA&Ms.
• Review DISA STIGs and SRGs to ensure systems are securely configured.
• Continuously monitor and evaluate security controls.
• Assist in identifying, investigating, and reporting security incidents or anomalies.
• Ensure compliance with federal guidelines regarding log management, system auditing, and boundary protections.
• Provide guidance to technical development, systems engineering, and management teams on cybersecurity matters.
• Ensure that software features, infrastructure updates, and system modifications adhere to security-by-design principles.
• Support the planning and execution of security control assessments performed by external assessment teams.
• Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field; equivalent professional experience may be considered.
• At least 5+ years of experience in cybersecurity, information assurance, or IT compliance.
• A minimum of 3+ years of hands-on experience guiding systems through the RMF process (Steps 1 through 7) to achieve successful ATO determinations.
• In-depth knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
• Direct experience with automated vulnerability assessment tools such as Nessus, ACAS, or SCC.
• Proven track record of managing and navigating security control databases like eMASS.
• Strong understanding of operating system security configurations for both Windows and Linux.
• Solid knowledge of network security architectures.
• Excellent technical writing skills, with the ability to create clear and structured compliance documentation.
• Outstanding communication and interpersonal skills.
• Active DoD 8570.01-M / DoD 8140 IAM Level II certification or higher, or a willingness to obtain one.
• U.S. citizenship is required.
• A minimum of Public Trust or favorably adjudicated Secret Clearance to start.
• Ability to comply with government cybersecurity policies, OPSEC rules, and secure system access regulations.
• Preferred: experience with FedRAMP, AWS GovCloud, Azure Government, secure software development, DevSecOps, Docker, Kubernetes, Section 508, defense contract execution, or secure federal program architectures.
• Opportunities for growth and development.
• A company certified as a Great Place to Work.
• Reasonable accommodations available if needed due to an applicant's or employee's disability.
Rimini Street
Rimini Street
Get handpicked remote jobs straight to your inbox weekly.